Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
119 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.23% | — | Le-pixel-solitaire Enhanced-youtube-shortcodeAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Le-Pixel-Solitaire Enhanced YouTube Shortcode enhanced-youtube-shortcode allows Stored XSS.This issue affects Enhanced YouTube Shortcode: from n/a through <= 2.0.1. | |
| Modificada | Media (6.1) | 0.17% | — | MDC Youtube Downloader Project MDC Youtube Downloader | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Nazmul Ahsan MDC YouTube Downloader mdc-youtube-downloader allows Stored XSS.This issue affects MDC YouTube Downloader: from n/a through <= 3.0.0. | |
| Aplazada | Media (6.4) | 0.27% | — | WP Youtube GalleryAI | 7/1/2025 | 17/6/2026 | The WP Youtube Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in all versions up to, and including, 1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Aplazada | Media (6.5) | 0.40% | — | Youmax Channel Embeds FOR Youtube BusinessesAI | 16/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in codehandling Youtube Video Grid youmax-channel-embeds-for-youtube-businesses allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Youtube Video Grid: from n/a through <= 1.9. | |
| Aplazada | Media (4.3) | 0.69% | — | Team Plugins360 Automatic Youtube GalleryAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Team Plugins360 Automatic YouTube Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Automatic YouTube Gallery: from n/a through 2.3.3. | |
| Aplazada | Alta (7.5) | 0.84% | — | Total-soft Video Gallery Youtube GalleryAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Video Gallery by Total-Soft Video Gallery – YouTube Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Video Gallery – YouTube Gallery: from n/a through 1.7.6. | |
| Aplazada | Media (6.4) | 0.41% | — | Streamweasels Youtube IntegrationAI | 28/11/2024 | 17/6/2026 | The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sw-youtube-embed' shortcode in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.47% | — | Ultimate Youtube Video Shorts Player With VimeoAI | 22/11/2024 | 17/6/2026 | The Ultimate YouTube Video & Shorts Player With Vimeo plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_setting() function in all versions up to, and including, 3.3. This makes it possible for authenticated attackers, with Subscriber-level access and above,… | |
| Analizada | Media (4.3) | 0.56% | — | Codelizar Ultimate Youtube Video & Shorts Player With Vimeo | 21/11/2024 | 17/6/2026 | The Ultimate YouTube Video & Shorts Player With Vimeo plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the del_ytsingvid() function in all versions up to, and including, 3.3. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Modificada | Media (5.4) | 0.31% | — | MDC Youtube Downloader Project MDC Youtube Downloader | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nazmul Ahsan MDC YouTube Downloader mdc-youtube-downloader allows DOM-Based XSS.This issue affects MDC YouTube Downloader: from n/a through <= 3.0.0. | |
| Aplazada | Media (6.4) | 0.38% | — | Streamweasels Youtube IntegrationAI | 29/10/2024 | 17/6/2026 | The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sw-youtube-embed shortcode in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Modificada | Media (5.4) | 0.27% | — | Themes4wp Youtube External Subtitles | 28/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themes4WP Themes4WP YouTube External Subtitles themes4wp-youtube-external-subtitles allows DOM-Based XSS.This issue affects Themes4WP YouTube External Subtitles: from n/a through <= 1.0. | |
| Modificada | Media (5.4) | 0.42% | — | Smashballoon Feeds FOR Youtube | 11/7/2024 | 17/6/2026 | The Feeds for YouTube (YouTube video, channel, and gallery plugin) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'youtube-feed' shortcode in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes… | |
| Aplazada | Alta (7.8) | 0.33% | — | Yt-dlpAIYt-dl Youtube-dlAI | 2/7/2024 | 17/6/2026 | `yt-dlp` and `youtube-dl` are command-line audio/video downloaders. Prior to the fixed versions, `yt-dlp` and `youtube-dl` do not limit the extensions of downloaded files, which could lead to arbitrary filenames being created in the download folder (and path traversal on Windows). Since `yt-dlp` and `youtube-dl` also… | |
| Analizada | Media (4.8) | 0.33% | — | Info-d-74 Playlist FOR Youtube | 29/5/2024 | 17/6/2026 | The Playlist for Youtube WordPress plugin through 1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (5.3) | 0.33% | — | Emarketdesign Youtube Video Gallery | 21/5/2024 | 17/6/2026 | The YouTube Video Gallery by YouTube Showcase – Video Gallery Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the emd_form_builder_lite_submit_form function in all versions up to, and including, 3.3.6. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.39% | — | WP Life Video Gallery API Gallery Youtube Vimeo Link GalleryAI | 6/5/2024 | 17/6/2026 | Missing Authorization vulnerability in A WP Life Video Gallery – Api Gallery, YouTube and Vimeo, Link Gallery.This issue affects Video Gallery – Api Gallery, YouTube and Vimeo, Link Gallery: from n/a through 1.5.3. | |
| Aplazada | Alta (8.3) | 0.44% | — | ZD Youtube FLV PlayerAI | 30/4/2024 | 17/6/2026 | The ZD YouTube FLV Player plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.2.6 via the $_GET['image'] parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used… | |
| Aplazada | Media (6.5) | 0.31% | — | Eric-oliver Machler Dsgvo YoutubeAI | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eric-Oliver Mächler DSGVO Youtube allows Stored XSS.This issue affects DSGVO Youtube: from n/a through 1.4.5. | |
| Modificada | Media (4.8) | 0.39% | — | Ternstyle Automatic Youtube Video Posts | 15/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ternstyle LLC Automatic Youtube Video Posts Plugin allows Stored XSS.This issue affects Automatic Youtube Video Posts Plugin: from n/a through 5.2.2. | |
| Modificada | Alta (8.8) | 0.26% | — | Superblogme Broken Link Checker FOR Youtube | 30/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Super Blog Me Broken Link Checker for YouTube allows Cross Site Request Forgery.This issue affects Broken Link Checker for YouTube: from n/a through 1.3. | |
| Modificada | Alta (8.8) | 0.31% | — | Urosevic MY Youtube Channel | 22/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Aleksandar Urošević My YouTube Channel plugin <= 3.23.3 versions. | |
| Modificada | Alta (8.8) | 0.28% | — | Alexufo Youtube Speedload | 16/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Alexufo Youtube SpeedLoad plugin <= 0.6.3 versions. | |
| Modificada | Media (5.4) | 0.31% | — | Getbutterfly Youtube Playlist Player | 18/10/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Ciprian Popescu YouTube Playlist Player plugin <= 4.6.7 versions. | |
| Modificada | Alta (8.8) | 0.21% | — | Galaxyweblinks Video Playlist FOR Youtube | 16/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Galaxy Weblinks Video Playlist For YouTube plugin <= 6.0 versions. |